A method and device for detecting illegal access of DRA equipment to network elements based on signaling fusion analysis technology

Through the DRA device illegal access detection method based on signaling fusion analysis technology, newly added links are identified and the threat behavior of their signaling data is detected. Combined with the network element access frequency judgment, it solves the gap in DRA device illegal access detection, improves detection efficiency and accuracy, and enhances the security of telecommunications networks.

CN119967416BActive Publication Date: 2025-09-26Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510124136.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-26
Publication Date
2025-09-26
Estimated Expiration
2045-01-26

AI Technical Summary

Technical Problem

The existing technology lacks an effective method for detecting illegal access of DRA devices, which threatens the security and reliability of telecommunications networks.

Method used

Based on signaling fusion analysis technology, the system identifies new links through the DRA link configuration table and performs threat behavior detection on their signaling data. At the same time, it calculates the network element access frequency, integrates the two detection methods for comprehensive judgment, and identifies illegally accessed network elements.

Benefits of technology

The efficiency and accuracy of DRA equipment's illegal access detection are improved, the probability of missed and misjudgment is reduced, and the security and reliability of telecommunications networks are enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119967416B_ABST
    Figure CN119967416B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of mobile communication networks and provides a method and device for detecting illegal access to network elements by DRA equipment based on signaling fusion analysis technology. The method identifies a newly added link based on the DRA link configuration table and performs threat behavior detection on the signaling data on the link to determine whether it is illegal access. At the same time, the access frequency of the network element is calculated and the illegal access is determined based on the indirect access characteristics. Finally, a comprehensive judgment is made by integrating the two detection methods. The present invention can timely detect illegal access behavior by performing newly added link detection through the DRA link configuration table, and detects according to the indirect access characteristics of the illegally accessed network element, which can improve the reliability and accuracy of DRA illegal access detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of mobile communication networks, and in particular relates to a method and device for detecting illegal access of DRA equipment to network elements based on signaling fusion analysis technology. Background Art

[0002] A DRA device is a device or functional entity used to route and forward Diameter signaling messages in a mobile communications network. It efficiently handles Diameter signaling interactions between different network elements, ensuring that the signaling reaches its target node accurately and without error. Illegal actors can infiltrate telecommunications network management equipment via the internet, add a virtual network element identity to the DRA device, and establish a signaling link with the DRA using this disguised identity. They then exploit vulnerabilities in the Diameter protocol to send carefully crafted signaling messages to the target network element, posing as legitimate entities to threaten and detect the target network element. After completing their mission, they typically delete all operation records, including configuration records, call logs, and data change notifications. This prevents administrators from detecting configuration data tampering and determining whether the DRA device has been illegally accessed. Unauthorized access to a DRA device can lead to serious consequences, including information leakage, service interruption, and tariff fraud.

[0003] At present, there is a lack of research on DRA device illegal access detection technology in this field. There is an urgent need for an efficient and accurate DRA device illegal access detection method to fill the gap in this research direction and improve the security and reliability of telecommunications networks. Summary of the Invention

[0004] In view of the lack of research on DRA device illegal access detection technology in the existing field, the present invention provides a DRA device illegal access network element detection method and device based on signaling fusion analysis technology. The method identifies new links based on the DRA link configuration table, performs threat behavior detection on the signaling data of the new links, and determines whether it is illegal access; at the same time, calculates the access frequency of the network element, determines whether it is illegal access based on the indirect access characteristics, and finally integrates the two detection methods to comprehensively determine whether it is illegal access behavior.

[0005] In a first aspect, the present invention provides a method for detecting illegal access of a DRA device to a network element based on signaling fusion analysis technology, comprising:

[0006] Step 1: Collect and store Diameter signaling data flowing through the DRA device, and obtain the link configuration table of the DRA device;

[0007] Step 2: Extracting link information from the collected Diameter signaling data flowing into the DRA device and comparing it with the link configuration table. If the link information is not in the link configuration table, it is determined to be a newly added link and the Diameter signaling data on the newly added link is output; if the link information is already in the link configuration table, it is determined to be a normal link.

[0008] Step 3: Perform threat behavior detection on the Diameter signaling data on the newly added link. If the Diameter signaling data is threat behavior signaling, determine that the newly added link is a DRA device illegally accessed link, and extract network element information based on the DRA device illegally accessed link and input it into a first illegally accessed network element set set1;

[0009] Step 4: Analyze the Diameter signaling data flowing through the DRA device, extract network element access time information, perform statistical analysis, and calculate the network element access frequency within a specified time period. The access frequency of each network element is determined. If any network element has an access frequency below a set threshold, it is marked as an indirect access network element, and network element information is extracted to obtain a second set of illegally accessed network elements, set 2.

[0010] Step 5: performing an intersection operation on the first illegally accessed network element set and the second illegally accessed network element set to obtain a final illegally accessed network element set.

[0011] Furthermore, step 1 adopts a full data collection method to collect Diameter signaling data flowing into and out of the DRA device in real time, parses the Diameter signaling data through a signaling parsing device, and stores the parsed data in a HIVE data warehouse according to data field specifications, and partitions the data by day.

[0012] Furthermore, obtaining the link configuration table of the DRA device in step 1 includes: logging into the DRA device management platform through an administrator account to directly obtain the link configuration table of the DRA device;

[0013] The method further includes: restoring the link configuration table of the DRA device by analyzing the Diameter signaling data and adopting a DRA device link information extraction algorithm.

[0014] Furthermore, the link configuration data in the link configuration table includes link type, source IP address, destination IP address, source port, destination port, source host name, destination host name, and link establishment time and shutdown time.

[0015] Furthermore, threat behavior detection is performed on the Diameter signaling data on the newly added link, specifically including: constructing a threat behavior detection rule table, and detecting the Diameter signaling data on the newly added link according to the threat behavior detection rule table.

[0016] Furthermore, the extraction of network element access time information and statistical analysis to calculate the network element access frequency within a specified time period includes: calculating the number of network element access times N of the i-th network element within the specified time period. i With the total number of access times N and access time T i The ratio of the total access time T to the access frequency f of the i-th network element is obtained. i :

[0017] f i =(N i / N)*(T i / T).

[0018] In a second aspect, the present invention provides a device for detecting illegal access of a DRA device to a network element based on signaling fusion analysis technology, comprising:

[0019] a Diameter signaling data collection unit, configured to collect and store Diameter signaling data flowing through a DRA device, and obtain a link configuration table of the DRA device;

[0020] a new link detection unit of the DRA device, configured to extract link information from Diameter signaling data collected and flowing into the DRA device, and compare the link information with the link configuration table; if the link information is not in the link configuration table, determine that the link is a new link and output the Diameter signaling data on the new link; if the link information is already in the link configuration table, determine that the link is a normal link;

[0021] a signaling data threat behavior detection unit, configured to perform threat behavior detection on Diameter signaling data on the newly added link; if the Diameter signaling data is threat behavior signaling, determine that the newly added link is a DRA device illegally accessed link; and extract network element information based on the DRA device illegally accessed link and input it into a first illegally accessed network element set set1;

[0022] an indirect access feature calculation unit, configured to analyze the Diameter signaling data flowing through the DRA device, extract network element access time information, perform statistical analysis, and calculate the network element access frequency within a specified time period; determine the access frequency of each network element, and if any network element has an access frequency lower than a set threshold, mark it as an indirect access network element, and extract network element information to obtain a second set of illegally accessed network elements, set2;

[0023] The DRA device illegal access comprehensive judgment unit is configured to perform an intersection operation on the first illegally accessed network element set and the second illegally accessed network element set to obtain a final illegally accessed network element set set.

[0024] The beneficial effects of the present invention are:

[0025] (1) The present invention detects newly added links of the DRA device based on the link configuration table of the DRA device, and performs threat behavior detection on the signaling data on the newly added links, identifies illegally accessed network elements on the DRA device, promptly discovers the threat behavior of illegally accessed network elements, and improves the detection efficiency of DRA illegal access.

[0026] (2) The present invention is based on the characteristics of illegally accessed network elements. Illegal access network elements usually appear indirectly and are non-periodic. By analyzing the access frequency of network elements and setting thresholds, the indirect access characteristics are identified, thereby improving the detection accuracy.

[0027] (3) The present invention avoids the limitations of a single detection method by integrating illegal access detection based on the DRA link configuration table and illegal access detection based on indirect access characteristics, effectively reduces the probability of missed judgments, misjudgments, etc., and improves the reliability and accuracy of illegal access detection of DRA equipment. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 A flowchart of a method for detecting illegal access of a DRA device to a network element based on signaling fusion analysis technology provided by an embodiment of the present invention;

[0029] Figure 2 A schematic diagram of collecting Diameter signaling data flowing through a DRA device provided by an embodiment of the present invention;

[0030] Figure 3 A structural diagram of a DRA device illegal access detection device based on signaling fusion analysis technology provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0031] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly described below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0032] As a routing forwarding point in a mobile communication network, the DRA device plays an important role in routing and forwarding Diameter signaling data. By illegally accessing the DRA device, criminals can detect and threaten the target network element, seriously affecting the security of the communication network. In view of the lack of methods for detecting illegal access to DRA devices in the current field, the present invention proposes a DRA illegal access detection method based on signaling fusion analysis. The method identifies newly added links according to the DRA link configuration table, and performs threat behavior detection on the signaling data on the link to determine whether it is an illegal access. At the same time, it calculates the access frequency of the network element and determines whether it is an illegal access based on the indirect access characteristics. Finally, a comprehensive judgment is made by integrating the two detection methods. The method can detect newly added links through the DRA link configuration table, which can timely discover illegal access behavior and improve the accuracy of DRA illegal access detection based on the indirect access characteristics of the illegally accessed network element.

[0033] like Figure 1 As shown, an embodiment of the present invention provides a method for detecting illegal access of a DRA device to a network element based on signaling fusion analysis technology, including:

[0034] Step 1: Collect Diameter signaling data and obtain the link configuration table of the DRA device. Collect and store the Diameter signaling data flowing through the DRA device, and obtain the link configuration table of the DRA device.

[0035] Specifically, if Figure 2 As shown, a full-data collection method is used to collect Diameter signaling data flowing into and out of the DRA device in real time. The Diameter signaling data is parsed by a signaling parser and stored in the HIVE data warehouse according to data field specifications. The data is then partitioned by day. There are two ways to obtain the link configuration table for the DRA device. Method 1: Log in to the DRA device management platform using an administrator account to directly obtain the DRA device's link configuration table, which includes the link type, source IP address, destination IP address, source port, destination port, source host name, destination host name, and link establishment and shutdown times. Method 2: Analyze historical collected Diameter signaling data and use the DRA device link information extraction algorithm to restore the DRA device's link configuration table. The DRA device link information extraction algorithm aggregates and counts Diameter signaling data based on fields such as link type, source IP address, destination IP address, source port, destination port, source host name, and destination host name. Correlation analysis is then performed on the results from multiple days to eliminate abnormal link data and restore the DRA device's link configuration table.

[0036] Step 2: Link information is extracted from the collected Diameter signaling data flowing into the DRA device and compared with the link configuration table. If the link information is not in the link configuration table, it is determined to be a new link and the Diameter signaling data on the new link is output. If the link information is already in the link configuration table, it is determined to be a normal link.

[0037] Step 3: Perform threat behavior detection on the Diameter signaling data on the newly added link. If the Diameter signaling data is a threat behavior signaling, the newly added link is determined to be an illegal access link of the DRA device, and the network element information is extracted based on the illegal access link of the DRA device and input into the first illegal access network element set set1 = {ne1, ne2…, ne j}, where ne1 is the first illegal network element in the first illegal access network element set.

[0038] Specifically, threat behavior detection is performed on Diameter signaling data on newly added links. This includes constructing a threat behavior detection rule table and then detecting Diameter signaling data on the newly added links based on the threat behavior detection rule table. Constructing the threat behavior detection rule table includes storing rule data based on the type of threat behavior detected, which is used to define and identify various threat behaviors, enabling the system to automatically detect and respond to potential security threats. For example, the threat behavior detection rule table is constructed based on fields such as Command-code, ApplicationId, Flags, Visited-PLMN-Id, and IDR-Flags for detection.

[0039] Step 4: By analyzing the Diameter signaling data flowing through the DRA device, extract the network element access time information and perform statistical analysis to calculate the network element access frequency within the specified time; and judge the access frequency of each network element. If there is a network element access frequency lower than the set threshold, it is marked as an indirect access network element, and the network element information is extracted to obtain the second illegal access network element set set2 = {ne1, ne2…, ne j}, where ne1 is the first illegal network element in the second illegal access network element set

[0040] The network element access time information is extracted and statistically analyzed to calculate the network element access frequency within the specified time, specifically including: calculating the number of network element access times N in the specified time period. i With the total number of access times N and access time T i The ratio of the total access time T to the access frequency f of the i-th network element is obtained. i :

[0041] f i =(N i / N)*(T i / T).

[0042] The access frequency of each network element is compared with a set threshold. If the access frequency is lower than the threshold δ, it is marked as an indirect access network element. The set of all indirect access network elements is the second illegal access network element set 2.

[0043] Step 5: Perform an intersection operation on the first set of illegally accessed network elements and the second set of illegally accessed network elements to obtain the final set of illegally accessed network elements set:

[0044] set=set1∩set2

[0045] The method provided by the present invention identifies newly added links based on the DRA link configuration table and performs threat behavior detection on the signaling data on the link to determine whether it is illegal access. It also calculates the access frequency of the network element and determines whether it is illegal access based on the indirect access characteristics. Finally, a comprehensive judgment is made by integrating these two detection methods. This method can detect newly added links based on the DRA link configuration table, which can promptly detect illegal access behavior. It also detects based on the indirect access characteristics of the illegally accessed network element, thereby improving the accuracy of DRA illegal access detection.

[0046] like Figure 3 As shown, an embodiment of the present invention further provides a DRA device illegal access detection device based on signaling fusion analysis technology, comprising:

[0047] A Diameter signaling data collection unit is used to collect and store Diameter signaling data flowing through the DRA device and obtain the link configuration table of the DRA device;

[0048] The new link detection unit of the DRA device is used to extract link information from the Diameter signaling data collected and flowing into the DRA device and compare it with the link configuration table. If the link information is not in the link configuration table, it is determined to be a new link and the Diameter signaling data on the new link is output. If the link information already exists in the link configuration table, it is determined to be a normal link.

[0049] a signaling data threat behavior detection unit, configured to perform threat behavior detection on Diameter signaling data on the newly added link; if the Diameter signaling data is threat behavior signaling, determine that the newly added link is a DRA device illegally accessed link; and extract network element information based on the DRA device illegally accessed link and input it into a first illegally accessed network element set set1;

[0050] an indirect access feature calculation unit, configured to analyze Diameter signaling data flowing through the DRA device, extract network element access time information, perform statistical analysis, and calculate the network element access frequency within a specified time period; determine the access frequency of each network element, and if any network element has an access frequency below a set threshold, mark it as an indirect access network element, and extract network element information to obtain a second set of illegally accessed network elements, set2;

[0051] The DRA device illegal access comprehensive judgment unit is used to perform an intersection operation on the first illegal access network element set and the second illegal access network element set to obtain a final illegal access network element set.

[0052] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A method for detecting illegal access of DRA devices to network elements based on signaling fusion analysis technology, characterized in that: include: Step 1: Collect and store Diameter signaling data flowing through the DRA device, and obtain the link configuration table of the DRA device; Step 2: Extracting link information from the collected Diameter signaling data flowing into the DRA device and comparing it with the link configuration table. If the link information is not in the link configuration table, it is determined to be a newly added link and the Diameter signaling data on the newly added link is output; if the link information is already in the link configuration table, it is determined to be a normal link. Step 3: Perform threat behavior detection on the Diameter signaling data on the newly added link. If the Diameter signaling data is threat behavior signaling, determine that the newly added link is a DRA device illegally accessed link, and extract network element information based on the DRA device illegally accessed link and input it into a first illegally accessed network element set set1; Step 4: Analyze the Diameter signaling data flowing through the DRA device, extract network element access time information, perform statistical analysis, and calculate the network element access frequency within a specified time period. The access frequency of each network element is determined. If any network element has an access frequency below a set threshold, it is marked as an indirect access network element, and network element information is extracted to obtain a second set of illegally accessed network elements, set 2. Step 5: performing an intersection operation on the first illegally accessed network element set and the second illegally accessed network element set to obtain a final illegally accessed network element set.

2. The method for detecting illegal access of DRA devices to network elements based on signaling fusion analysis technology according to claim 1, characterized in that: The step 1 adopts a full data collection method to collect the Diameter signaling data flowing into and out of the DRA device in real time, parses the Diameter signaling data through a signaling parsing device, and stores the parsed data in a HIVE data warehouse according to data field specifications, and partitions the data by day.

3. The method for detecting illegal access of DRA devices to network elements based on signaling fusion analysis technology according to claim 1, characterized in that: Obtaining the link configuration table of the DRA device in step 1 includes: logging into the DRA device management platform through an administrator account and directly obtaining the link configuration table of the DRA device; The method further includes: restoring the link configuration table of the DRA device by analyzing the Diameter signaling data and adopting a DRA device link information extraction algorithm.

4. The method for detecting illegal access of DRA devices to network elements based on signaling fusion analysis technology according to claim 1, characterized in that: The link configuration data in the link configuration table includes link type, source IP address, destination IP address, source port, destination port, source host name, destination host name, and link establishment time and shutdown time.

5. The method for detecting illegal access of DRA devices to network elements based on signaling fusion analysis technology according to claim 1, characterized in that: Performing threat behavior detection on the Diameter signaling data on the newly added link specifically includes: constructing a threat behavior detection rule table, and detecting the Diameter signaling data on the newly added link according to the threat behavior detection rule table.

6. The method for detecting illegal access of DRA devices to network elements based on signaling fusion analysis technology according to claim 1, characterized in that: The extraction of network element access time information and statistical analysis to calculate the network element access frequency within a specified time period includes: calculating the number of network element access times N of the i-th network element within the specified time period. i With the total number of access times N and access time T i The ratio of the total access time T to the access frequency f of the i-th network element is obtained. i : f i =(N i / N)*(T i / T)。 7. A DRA device illegal access detection device based on signaling fusion analysis technology, characterized in that: include: a Diameter signaling data collection unit, configured to collect and store Diameter signaling data flowing through a DRA device, and obtain a link configuration table of the DRA device; a new link detection unit of the DRA device, configured to extract link information from Diameter signaling data collected and flowing into the DRA device, and compare the link information with the link configuration table; if the link information is not in the link configuration table, determine that the link is a new link and output the Diameter signaling data on the new link; if the link information is already in the link configuration table, determine that the link is a normal link; a signaling data threat behavior detection unit, configured to perform threat behavior detection on Diameter signaling data on the newly added link; if the Diameter signaling data is threat behavior signaling, determine that the newly added link is a DRA device illegally accessed link; and extract network element information based on the DRA device illegally accessed link and input it into a first illegally accessed network element set set1; an indirect access feature calculation unit, configured to analyze the Diameter signaling data flowing through the DRA device, extract network element access time information, perform statistical analysis, and calculate the network element access frequency within a specified time period; determine the access frequency of each network element, and if any network element has an access frequency lower than a set threshold, mark it as an indirect access network element, and extract network element information to obtain a second set of illegally accessed network elements, set2; The DRA device illegal access comprehensive judgment unit is configured to perform an intersection operation on the first illegally accessed network element set and the second illegally accessed network element set to obtain a final illegally accessed network element set set.

Citation Information

Patent Citations

  • Diameter flooding attack detection device and method

    CN109040127A

  • 4G mobile communication network HSS signaling protection method and device

    CN113115314A